New SharePoint auth bypass already being exploited hours after PoC went public

Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint’s JWT token validation that lets an attacker impersonate any user or admin without credentials. Threat intel firm Defused reported the exploit code was already hitting its honeypots the same day; it’s the second distinct on-prem SharePoint flaw to make news this week, after Monday’s ransomware-exploited deserialization bug.

More info here: CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Roman Sannikov, Global Research Coordinator, iCOUNTER said this:

“Microsoft patched CVE-2026-55040 in July. Rapid7 published a full technical write-up and working exploit code today, and Defused was already seeing that exact code hit its honeypots the same day. Hours passed between a researcher publishing proof-of-concept code and someone using it against real targets. No group has been identified yet, which tracks, at this stage it’s likely opportunistic scanning off the public PoC rather than a targeted campaign. This is exactly the kind of flaw that matters more as companies move away from plain passwords. CVE-2026-55040 breaks the token validation that’s supposed to replace passwords in the first place, and we’re seeing threat actors go after tokens and other forms of MFA directly instead of trying to phish or guess a credential. The bigger pattern is worth focusing reporting on: this is the second separate on-prem SharePoint flaw in the news this week. The story now is how many separate ways into the same platform are surfacing at once.”

This is fixed and people should update all the things. That would mitigate this issue completely. Otherwise pwnage will be guaranteed.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading